Search Privacy Fines

Browse and filter privacy enforcement fines worldwide.

← Back to Overview

151 fines found

Total: $190.9M

DateCompanyFineRegulationAuthorityCountryTypeSummary
2019-07-30Unknown€80KGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to implement sufficient measures to ensure information security
Two companies working in finances didn’t follow the procedure when disposing of ...

Two companies working in finances didn’t follow the procedure when disposing of personal data.

Articles: Art. 32 GDPR

2019-04-04Company in the financial sector€80KGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 5 GDPR, Art. 32 GDPR

2019-07-30Unknown€80KGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2019-07-30Unknown€80KGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to implement sufficient measures to ensure information security
In a digital publication, health data was accidentally published due to inadequa...

In a digital publication, health data was accidentally published due to inadequate internal control mechanisms.Due to inadequate internal control mechanisms, health data was made public by a digital publication.

Articles: Art. 32 GDPR

2019-10-17Unknown€80KGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2019-07-30Unknown€80KGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2020-01-01Company€65KGDPRData Protection Authority of NiedersachsenGermanyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2019-01-01Meta Platforms€51KGDPRData Protection Authority of HamburgGermanyFailure to appoint a data protection officer
The German branch of Facebook was fined by €51,000 because it failed to appoint ...

The German branch of Facebook was fined by €51,000 because it failed to appoint a data protection officer. Facebook argued that it did in fact appoint a data protection officer in Ireland who acted as a data protection officer for all the local European Facebook branches. The Data Protection Authority of Hamburg, however, argued that Facebook did not notify the German authority about this appointment, and as such, the fine is valid. The reason the fine was relatively small was that Facebook did, after all, appoint a DPO but failed to notify German authorities. The fine was given to Facebook Germany GmbH, which is the local German branch of the company.The fine was issued sometimes in 2019 but was only made public by the Data Protection Authority of Hamburg in February 2020. The exact date of the fine was not revealed.

Articles: Art. 37 GDPR

2019-01-01Meta Platforms€51KGDPRData Protection Authority of HamburgGermanyFailure to appoint a data protection officer
--

Articles: Art. 37 GDPR

2019-03-01N26€50KGDPRData Protection Authority of BerlinGermanyNon-compliance with lawful basis for data processing
A bank had retained the personal data of former customers in order to create a b...

A bank had retained the personal data of former customers in order to create a blacklist. Apparently, they wanted to prevent those customers from opening up new accounts at their bank because they were suspected of money laundering. While the bank wanted to hand-wave away this unlawful act by appealing to the German Banking Act, the Berlin Supervisory Authority found this to be illegal.

Articles: Art. 6 GDPR

2019-03-01N26€50KGDPRData Protection Authority of BerlinGermanyNon-compliance with lawful basis for data processing
--

Articles: Art. 6 GDPR

--Unknown€50KGDPRData Protection Authority of BrandenburgGermanyNon-compliance with subjects' rights protection safeguards
--

Articles: Art. 15 GDPR, Art. 28 GDPR

2022-09-21Property development company€50KGDPRData Protection Authority of Baden-WuerttembergGermanyNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) GDPR, Art. 14 GDPR

2019-01-01https://datenschutz-hamburg.de/assets/pdf/28._Taetigkeitsbericht_Datenschutz_2019_HmbBfDI.pdf€20KGDPRData Protection Authority of HamburgGermanyFailure to implement sufficient measures to ensure information security
HVV GmbH had not reported a data breach to the data protection authority in due ...

HVV GmbH had not reported a data breach to the data protection authority in due time. This data breach was related to the security gap in the Customer E-Service, in that that clients with an HVV card who logged in the CES could access the data of other customers by changing the URL to match their data profile.

Articles: Art. 33 GDPR, Art. 34 GDPR

2019-01-01https://datenschutz-hamburg.de/assets/pdf/28._Taetigkeitsbericht_Datenschutz_2019_HmbBfDI.pdf€20KGDPRData Protection Authority of HamburgGermanyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 33 GDPR, Art. 34 GDPR

2018-11-21Knuddels.de€20KGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to implement sufficient measures to ensure information security
A hack revealed the personal data that included email addresses and passwords of...

A hack revealed the personal data that included email addresses and passwords of around 330,000 users.

Articles: Art. 32 GDPR

2018-12-01Unknown€20KGDPRData Protection Authority of HamburgGermanyInformation obligation non-compliance
--

Articles: Art. 83 (4) a) GDPR, Art. 33 (1) GDPR, Art. 34 (1) GDPR

2018-11-21Knuddels.de€20KGDPRData Protection Authority of Baden-WuerttembergGermanyFailure to implement sufficient measures to ensure information security
--

Articles: Art. 32 GDPR

2018-12-01Unknown€20KGDPRData Protection Authority of HamburgGermanyInformation obligation non-compliance
A data breach was not notified in time and the affected subjects were not made a...

A data breach was not notified in time and the affected subjects were not made aware.

Articles: Art. 83 (4) a) GDPR, Art. 33 (1) GDPR, Art. 34 (1) GDPR

2022-01-01Company€20KGDPRThe DPA of BremenGermanyUnknown
--

Articles: Unknown

2022-01-01Covid-19 Test Center€16KGDPRData Protection Authority of HessenGermanyNon-compliance with lawful basis for data processing
--

Articles: Art. 6 (1) GDPR, Art. 33 (1), (5) GDPR

2021-01-01Energy supplier€13KGDPRData Protection Authority of HambunrgGermanyUnknown
--

Articles: Unknown

2021-01-01Energy Supplier€13KGDPRData Protection Authority of SaxonyGermanyUnknown
--

Articles: Unknown

2021-01-01Car trading group€10KGDPRData Protection Authority of HamburgGermanyUnknown
--

Articles: Unknown

2019-12-09Rapidata GmbH€10KGDPRThe Federal Commissioner for Data Protection and Freedom of Information (BfDI)GermanyNo data protection officer appointed
The Federal Commissioner for Data Protection and Freedom of Information (BfDI) h...

The Federal Commissioner for Data Protection and Freedom of Information (BfDI) ha repeatedly requested the company to appoint a data protection officer in accordance with Article 37 GDPR but even so, Rapidata GmbH refused to do so. The company was fined with €10,000.

Articles: Art. 37 GDPR

PreviousPage 2 of 7Next